Information Disclosure Vulnerability in Microsoft Excel by Microsoft
CVE-2019-1446

5.5MEDIUM

Key Information:

Summary

An information disclosure vulnerability exists in Microsoft Excel that allows for the improper disclosure of memory contents, potentially leading to sensitive data exposure. This flaw can be exploited by attackers to gain access to confidential information that should remain protected within the application. It emphasizes the need for users to apply the latest security patches and maintain vigilance against potential exploits.

Affected Version(s)

Excel Services on Microsoft SharePoint Server 2010 Service Pack 2 = unspecified

Microsoft Excel 2010 Service Pack 2 (32-bit editions)

Microsoft Excel 2010 Service Pack 2 (64-bit editions)

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.